Skip to content

deps(uv): bump the uv-minor-patch group with 25 updates - #2030

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/uv-minor-patch-242ba10dc0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/uv-minor-patch-242ba10dc0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv-minor-patch group with 25 updates:

Package From To
fonttools 4.65.0 4.66.0
pyparsing 3.3.2 3.3.3
pyjwt 2.14.0 2.15.0
sqlalchemy 2.0.54 2.1.1
starlette 1.6.0 1.7.0
uvicorn 0.53.0 0.54.0
webauthn 3.0.0 3.0.1
oracledb 26.0.0 26.0.1
pymongo 4.18.1 4.18.2
snowflake-connector-python 4.7.4 4.7.5
pillow-heif 1.7.0 1.8.0
opentelemetry-api 1.44.0 1.45.0
opentelemetry-sdk 1.44.0 1.45.0
opentelemetry-exporter-otlp 1.44.0 1.45.0
opentelemetry-instrumentation-fastapi 0.65b0 0.66b0
opentelemetry-instrumentation-sqlalchemy 0.65b0 0.66b0
opentelemetry-instrumentation-logging 0.65b0 0.66b0
hypothesis 6.168.0 6.168.1
httpx2 2.13.0 2.13.1
markdown 3.10.3 3.11
ruff 0.16.8 0.16.9
httpcore2 2.13.0 2.13.1
platformdirs 4.11.11 4.11.14
soupsieve 2.9.2 2.10
virtualenv 21.9.0 21.12.1

Updates fonttools from 4.65.0 to 4.66.0

Release notes

Sourced from fonttools's releases.

4.66.0

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;adobe-type-tools/feature_file_workshops#8dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations, which can reach outside the font-level ranges (#4190, #4193).
  • [bezierTools] Preserve exact endpoints in splitQuadraticAtT and splitCubicAtTC as well, like splitCubicAtT since 4.55.4 (#3742, #4194).
  • [bezierTools] Fix ZeroDivisionError in lineLineIntersections for collinear vertical lines; they are now treated as parallel like horizontal ones (#3515, #4181).
  • [subset] pyftsubset now preserves the input font's flavor (WOFF, WOFF2) when --flavor is omitted, instead of writing uncompressed sfnt data under the same extension; pass --flavor=none to force uncompressed output (#3630, #4182).
  • [merge] Report incompatible unitsPerEm values by name, with the input values, instead of a bare assertion (#2844, #4184).
  • [designspaceLib] Fix the type annotation and documentation of DesignSpaceDocument.default, which holds a SourceDescriptor, not a source name (#2994, #4186).
  • [ttLib.sfnt] Raise TTLibError instead of AssertionError for inconsistent WOFF table, metadata and private-data lengths, so the checks also hold under python -O (#4178).
  • [misc.etree] Disable entity resolution altogether on lxml >= 5.0 as well: lxml's resolve_entities="internal" still fetched external parameter entities before lxml 6.1.3, so a crafted DTD could read local files into parsed XML content (#4195).
  • [cmap] Bound the expansion of format 4 segments and format 12/13 groups when decompiling, like HarfBuzz does: groups are clamped to U+10FFFF, inverted or overlapping groups are skipped with a warning, and groups mapped to the missing glyph are not expanded. A crafted font could previously exhaust memory with a single group ending at 0xFFFFFFFF (#4204).
  • [varLib.avar] Escape axis names and tags when varLib.avar.unbuild emits its designspace snippet, so a crafted font cannot inject markup (#4203).
Changelog

Sourced from fonttools's changelog.

4.66.0 (released 2026-09-23)

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;, as Glyphs does and as proposed for the spec adobe-type-tools/feature_file_workshops#8 references are registered under every listed language. dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations, which can reach outside the font-level ranges (#4190, #4193).
  • [bezierTools] Preserve exact endpoints in splitQuadraticAtT and splitCubicAtTC as well, like splitCubicAtT since 4.55.4 (#3742, #4194).
  • [bezierTools] Fix ZeroDivisionError in lineLineIntersections for collinear vertical lines; they are now treated as parallel like horizontal ones (#3515, #4181).
  • [subset] pyftsubset now preserves the input font's flavor (WOFF, WOFF2) when --flavor is omitted, instead of writing uncompressed sfnt data under the same extension; pass --flavor=none to force uncompressed output (#3630, #4182).
  • [merge] Report incompatible unitsPerEm values by name, with the input values, instead of a bare assertion (#2844, #4184).
  • [designspaceLib] Fix the type annotation and documentation of DesignSpaceDocument.default, which holds a SourceDescriptor, not a

... (truncated)

Commits
  • f54ab64 Release 4.66.0
  • 18dd898 Update NEWS.rst [skip ci]
  • 116a3f0 Merge pull request #4204 from fonttools/cmap12-bound-group-ranges
  • 083571a [cmap] Bound format 4 and 12/13 range expansion like HarfBuzz
  • 236a218 Merge pull request #4199 from tomekthewo/cff2-stale-varstore-cache
  • 0fccde3 Merge pull request #4203 from insaf021/avar-unbuild-escape-axis-names
  • fe7aa95 escape name-table axis names in varLib.avar.unbuild output
  • 460d36e Merge pull request #4202 from fonttools/feaLib-multi-language-fixups
  • a402e4e [feaLib] Test that statement_keywords covers parse_block
  • 9939b30 [feaLib] Reject dflt combined with other language tags
  • Additional commits viewable in compare view

Updates pyparsing from 3.3.2 to 3.3.3

Changelog

Sourced from pyparsing's changelog.

Version 3.3.3 - in development

  • Added support for Python 3.15.

  • Parse actions that return a tuple value for a named expression formerly saved just the first value of the tuple. Now they return the entire tuple. Partially fixes Issue #401, PR #640 submitted by Vincent Gao et AI.

  • Fixed CI unit test jobs selecting a tox environment with no test commands. The matrix and fallback now select py-unit, as diagnosed and proposed by glaziermag in issue #662; submitted by Neal Lin et AI.

  • Fixed Dict returning an empty nested ParseResults.as_dict() as [] instead of {}. Incorporates partial solution submitted in PR #635 submitted by Leo Ji.

    Additional fixes found as part of this work:

    • Removed vestigial unused ParseResults._modal attribute.

    • Fixed incidental bug when Dict tries to create a dict with a ParseResults value for a key (not hashable).

  • Fixed Word(..., max=n) raising instead of matching up to max characters when the character set contained whitespace - Word(nums, max=3) and Word(nums + " ", max=3) gave opposite results on the same input. Now both forms match up to max and leave the rest for the next parser. PR #646 submitted by Andrew Chen et AI.

  • Fixed QuotedString stripping whitespace that is part of a multi-character quote delimiter, e.g. the leading newline in QuotedString("\n;", multiline=True). The delimiter was silently collapsed to ";", so the newline was ignored when matching. QuotedString now only rejects quote_char/end_quote_char values that are empty or entirely whitespace, and preserves any surrounding whitespace that is part of a valid delimiter. Reported in issue #492.

  • Fixed pyparsing_common.as_datetime raising Invalid date/time: microsecond must be in 0..999999 for valid ISO-8601 timestamps whose fractional seconds round up to a full second (e.g. 2021-06-15T12:30:59.9999995, common in nanosecond-precision timestamps). The rounded microseconds are now added via timedelta so the value carries into the next second instead of overflowing the datetime microsecond argument. PR submitted by Andrew Chen et AI.

  • Fixed debug output corruption when a parsed line contains a carriage return or other control character. set_debug() printed the source line verbatim, so a stray \r returned the terminal cursor to column 0 and overwrote the "Match ... at loc" text. Control characters in the debug line are now shown escaped, and the marker caret stays aligned with the match location. Issue #496, reported by Matthew Rowles.

... (truncated)

Commits
  • d90d38b Update flit version and exclusion of generated railroad diagrams from source ...
  • 4220992 Updated CI to execute unit tests, PR #663; update test_unit.py to add test ca...
  • e266043 Reworked internal recursive implementations to use local stack vars or iterat...
  • See full diff in compare view

Updates pyjwt from 2.14.0 to 2.15.0

Release notes

Sourced from pyjwt's releases.

2.15.0

See the 2.15.0 changelog for complete release details.

Changelog

Sourced from pyjwt's changelog.

v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0>__

Security


- Wrap recursion errors from deeply nested JWT payloads in ``DecodeError``
  instead of exposing a raw ``RecursionError``.

Added


- Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) &lt;https://github.com/jpadilla/pyjwt/pull/1202&gt;`__

Changed

  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__
  • PyJWKClient.fetch_data() now raises PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;) when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError(&quot;The JWKS endpoint did not return a JSON
  object&quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) &lt;https://github.com/jpadilla/pyjwt/issues/914&gt;`__ and
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
  ``fetch_data()`` override that filters or transforms the JWKS is no longer
  undone by the next cache hit in
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
  ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
  non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
  match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
  ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a> chore: prepare 2.15.0 release</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a> fix: make recursive payload tests deterministic</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a> fix: normalize recursive JWT payload errors</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a> utils: mention bytes in force_bytes type error (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a> docs/conf: drop duplicate 'and' from read() docstring (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a> Add support for Python 3.15 (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a> Catch http.client.HTTPException in PyJWKClient.fetch_data (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a> fix: correct docstring typo in _validate_jti (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a> docs: clarify JWK certificate member handling (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li>
<li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&quot;&gt;compare view</a></li>
</ul>
</details>

<br />

Updates sqlalchemy from 2.0.54 to 2.1.1

Release notes

Sourced from sqlalchemy's releases.

2.1.1

Released: September 25, 2026

platform

  • [platform] [bug] Removed the legacy underscore-separated extra names such as mssql_pymssql and postgresql_psycopg from pyproject.toml. They normalize to the same names as the existing dash-separated extras, which is disallowed by PEP 685, and caused the 2.1.0 source distribution to fail to build with installers that enforce this rule, such as uv. The underscore spellings continue to work when installing, as installers normalize extra names before matching them.

    References: #13604

2.1.0

Released: September 24, 2026

orm

  • [orm] [feature] Added _orm.composite.column_template parameter to _orm.composite(). When the composite class is a dataclass, this parameter accepts a string template such as "person_%s", containing exactly one %s placeholder, that's used to generate column names for dataclass fields that don't otherwise have an explicit name, rather than using the bare field name. This removes the need to hand-write a _orm.mapped_column() for each field when the same composite dataclass is mapped multiple times on the same class with different column-name prefixes. Pull request courtesy Leonardo Rosa.

    References: #12575

  • [orm] [bug] Fixed issue where pickling an ORM object that had an instance level lazy loader established, such as when the _orm.raiseload() option is used, would emit a spurious warning regarding the loader containing additional criteria, if the object had itself been unpickled from a previous serialization. This would occur for objects that cross more than one serialization boundary, such as when using multiprocessing.

    This change is also backported to: 2.0.53

    References: #13574

  • [orm] [bug] Fixed issue where calling _orm.aliased() against an existing _orm.aliased() construct, without passing an explicit selectable, would disregard the selectable of the existing construct and produce an

... (truncated)

Commits

Updates starlette from 1.6.0 to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

Full changelog: 1.6.0...1.7.0

Changelog

Sourced from starlette's changelog.

1.7.0 (September 23, 2026)

This release adds experimental OpenTelemetry tracing and requires AnyIO 4.

!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period #3574.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.
Commits
  • 2269e9a Version 1.7.0 (#3575)
  • 4fe55eb Preserve FileResponse status for range requests (#3568)
  • 1f08daf Mark OpenTelemetryMiddleware as experimental (#3574)
  • 57de5fa Support HTTP response trailers in TestClient (#3563)
  • 03f12b7 Allow HTTPException to use non-standard status codes (#3545)
  • 76fd00f Reject WebSocket requests to StaticFiles (#3532)
  • f03f65c docs: fix 'its not available' and 'This ensure' wording (#3526)
  • 485aca4 docs: the test client is built on httpx2, not httpx (#3525)
  • fd662b1 Implement identity on SimpleUser and UnauthenticatedUser (#3271)
  • 41db6a7 Stabilize CodSpeed upload buffer allocations (#3524)
  • Additional commits viewable in compare view

Updates uvicorn from 0.53.0 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)
Commits

Updates webauthn from 3.0.0 to 3.0.1

Release notes

Sourced from webauthn's releases.

v3.0.1

Changes:

  • verify_registration_response() now rejects responses with attestation statement formats that are not strings (#288, h/t @​DarkaMaul)
Changelog

Sourced from webauthn's changelog.

v3.0.1

Changes:

  • verify_registration_response() now rejects responses with attestation statement formats that are not strings (#288, h/t @​DarkaMaul)
Commits
  • d72e0f5 Bump version to v3.0.1
  • 732ca23 Update CHANGELOG for v3.0.1
  • b474c8d Merge pull request #288 from trail-of-forks/dm/reject-attestations-fmt
  • 5557d97 Reject early invalid attestation formats
  • See full diff in compare view

Updates oracledb from 26.0.0 to 26.0.1

Release notes

Sourced from oracledb's releases.

v26.0.1

python-oracledb 26.0.1 is now released. This release addresses a number of issues. See the full release notes for all of the details.

Commits
  • cf7d2aa Preparing to release python-oracledb 26.0.1.
  • 145ea2b Fixed bug causing hang with NUMBER input and SYS_REFCURSOR output bind
  • 6748825 Fixed bugs with handling duplicate data when fetching Arrow data frames
  • ba3bdd2 Fixed bug with handling the empty (default) value of the
  • 68dde29 Simplify tests.
  • 717aba0 Fixed regression with connecting to listeners that require TLS renegotiation
  • 619ac1e Bump version in preparation for new changes.
  • See full diff in compare view

Updates pymongo from 4.18.1 to 4.18.2

Release notes

Sourced from pymongo's releases.

PyMongo 4.18.2

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-2-released/343732

CVE-2026-96749 CVE-2026-96748 CVE-2026-96747

Changelog

Sourced from pymongo's changelog.

Changes in Version 4.18.2 (2026/09/24)

Version 4.18.2 is a bug fix release.

  • Hardened the bson buffer size guard against signed integer overflow. (CVE-2026-96749_).
  • Fixed connection string parsing to percent-decode each host individually. (CVE-2026-96748_).
  • Client-side field level encryption now rejects a KMS endpoint ending in .sock. (CVE-2026-96747_).

.. _CVE-2026-96749: https://www.cve.org/CVERecord?id=CVE-2026-96749 .. _CVE-2026-96748: https://www.cve.org/CVERecord?id=CVE-2026-96748 .. _CVE-2026-96747: https://www.cve.org/CVERecord?id=CVE-2026-96747

Issues Resolved ...............

See the PyMongo 4.18.2 release notes in JIRA_ for the list of resolved issues in this release.

.. _PyMongo 4.18.2 release notes in JIRA: https://jira.mongodb.org/secure/ReleaseNote.jspa?projectId=10004&version=52896

Commits

Updates snowflake-connector-python from 4.7.4 to 4.7.5

Release notes

Sourced from snowflake-connector-python's releases.

4.7.5

Fixes

  • Follow-up to the v4.7.4 incomplete-result fix (SNOW-4109042): when a successful query-request has an incomplete inline first chunk, the connector re-fetches the finished query once via GET /queries/{qid}/result before building the result set. JSON treats empty or shorter-than-declared inline rowsets as incomplete; Arrow only treats a missing/empty rowsetBase64 as incomplete so the execute hot path does not decode IPC. If the result GET fails (transport error or success: false), the original payload is kept; if the GET succeeds but is still incomplete, that response is used. In either incomplete case the existing rowcount/total checks still raise OperationalError errno 252013 when the result is drained (no silent EOF). On the sync path, a remote result chunk whose body holds fewer rows than its declared rowCount is re-downloaded once before that check raises, so a truncated-but-valid chunk download can recover without silent data loss. Asynchronous (snowflake.connector.aio) remote-chunk re-download is unchanged. set. Both the sync and async paths are fixed (SNOW-4109042).
  • Fixed a TLS handshake failure that cannot succeed on a retry — a minimum-version mismatch, an untrusted certificate, a hostname mismatch — being reported by connect() as a generic 250001: Could not connect to Snowflake backend after N attempt(s) alongside a firewall-troubleshooting hint. The network layer already identified and named such failures, but the authentication layer retried them until the login timeout expired and then replaced the diagnosis. They now surface as NonRetryableTlsError (a subclass of OperationalError keeping the same errno, so existing handlers are unaffected) naming the underlying cause, and are no longer retried. Transient handshake faults (ECONNRESET, unexpected EOF) remain retryable.

Features

  • Added the SNOWFLAKE_MIN_TLS_VERSION environment variable (1.2, 1.3, TLSv1.2 or TLSv1.3, defaulting to TLS 1.2) to raise the minimum TLS version on every outbound connection a synchronous connector makes: the Snowflake API, stage transfers, OCSP/CRL fetches, platform detection, IdP requests, AWS SDK requests (workload identity STS calls and the platform-detection identity probe) and Azure AD token requests made by azure-identity. An unrecognized value is rejected at connect time.
Commits
  • 7eed898 SNOW-4109042: re-download remote chunks that under-fill rowCount
  • 5848911 Bump up version to 4.7.5
  • 2be12fb SNOW-4017190 Add min TLS version knob to sync path
  • 3787518 SNOW-4109042: re-fetch result when the inline first chunk is incomplete
  • See full diff in compare view

Updates pillow-heif from 1.7.0 to 1.8.0

Release notes

Sourced from pillow-heif's releases.

v1.8.0

Added

  • Reading of entity groups: entity_groups key in info dictionary, tells which images form a stereo pair in spatial photos. #476
  • Decoding of embedded thumbnails: HeifImage.get_thumbnail method and draft in the Pillow plugin, Image.thumbnail() uses them instead of decoding the full image. #477

Changed

  • Minimum required libheif version is 1.23.4. #480
  • libheif was updated from the 1.23.3 to 1.23.4 version. #479
  • libde265 was updated from the 1.1.2 to 1.1.3 version. #483

Fixed

  • Segmentation fault when opening a file whose metadata item type is not valid UTF-8. #478
  • Pillow plugin: load() of a multi-frame image reloaded the frame data on every call, discarding in-place changes and failing after thumbnail(). #477
  • A depth image of an item type that libheif cannot decode made the whole file unreadable with libheif 1.23.4, such depth images are now skipped. #480
  • Type checkers treated the names imported from pillow_heif as private since the py.typed marker was added in 1.7.0: Pyright/Pylance and mypy --strict reported them as not exported, Pyright/Pylance autocompletion did not offer them. #490 Thanks to @​BetoFernandez123
Changelog

Sourced from pillow-heif's changelog.

[1.8.0 - 2026-09-22]

Added

  • Reading of entity groups: entity_groups key in info dictionary, tells which images form a stereo pair in spatial photos. #476
  • Decoding of embedded thumbnails: HeifImage.get_thumbnail method and draft in the Pillow plugin, Image.thumbnail() uses them instead of decoding the full image. #477

Changed

  • Minimum required libheif version is 1.23.4. #480
  • libheif was updated from the 1.23.3 to 1.23.4 version. #479
  • libde265 was updated from the 1.1.2 to 1.1.3 version. #483

Fixed

  • Segmentation fault when opening a file whose metadata item type is not valid UTF-8. #478
  • Pillow plugin: load() of a multi-frame image reloaded the frame data on every call, discarding in-place changes and failing after thumbnail(). #477
  • A depth image of an item type that libheif cannot decode made the whole file unreadable with libheif 1.23.4, such depth images are now skipped. #480
  • Type checkers treated the names imported from pillow_heif as private since the py.typed marker was added in 1.7.0: Pyright/Pylance and mypy --strict reported them as not exported, Pyright/Pylance autocompletion did not offer them. #490 Thanks to @​BetoFernandez123
Commits
  • 1486e9f v1.8.0
  • 1ffdd5d fix: names imported from pillow_heif were priv...

    Description has been truncated

Bumps the uv-minor-patch group with 25 updates:

| Package | From | To |
| --- | --- | --- |
| [fonttools](https://github.com/fonttools/fonttools) | `4.65.0` | `4.66.0` |
| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.3.2` | `3.3.3` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.14.0` | `2.15.0` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.54` | `2.1.1` |
| [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.53.0` | `0.54.0` |
| [webauthn](https://github.com/duo-labs/py_webauthn) | `3.0.0` | `3.0.1` |
| [oracledb](https://github.com/oracle/python-oracledb) | `26.0.0` | `26.0.1` |
| [pymongo](https://github.com/mongodb/mongo-python-driver) | `4.18.1` | `4.18.2` |
| [snowflake-connector-python](https://github.com/snowflakedb/snowflake-connector-python) | `4.7.4` | `4.7.5` |
| [pillow-heif](https://github.com/bigcat88/pillow_heif) | `1.7.0` | `1.8.0` |
| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-instrumentation-fastapi](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.65b0` | `0.66b0` |
| [opentelemetry-instrumentation-sqlalchemy](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.65b0` | `0.66b0` |
| [opentelemetry-instrumentation-logging](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.65b0` | `0.66b0` |
| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.168.0` | `6.168.1` |
| [httpx2](https://github.com/pydantic/httpx2) | `2.13.0` | `2.13.1` |
| [markdown](https://github.com/Python-Markdown/markdown) | `3.10.3` | `3.11` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.8` | `0.16.9` |
| [httpcore2](https://github.com/pydantic/httpx2) | `2.13.0` | `2.13.1` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.11` | `4.11.14` |
| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.9.2` | `2.10` |
| [virtualenv](https://github.com/pypa/virtualenv) | `21.9.0` | `21.12.1` |


Updates `fonttools` from 4.65.0 to 4.66.0
- [Release notes](https://github.com/fonttools/fonttools/releases)
- [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst)
- [Commits](fonttools/fonttools@4.65.0...4.66.0)

Updates `pyparsing` from 3.3.2 to 3.3.3
- [Release notes](https://github.com/pyparsing/pyparsing/releases)
- [Changelog](https://github.com/pyparsing/pyparsing/blob/master/CHANGES)
- [Commits](pyparsing/pyparsing@3.3.2...3.3.3)

Updates `pyjwt` from 2.14.0 to 2.15.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.14.0...2.15.0)

Updates `sqlalchemy` from 2.0.54 to 2.1.1
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `starlette` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `uvicorn` from 0.53.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

Updates `webauthn` from 3.0.0 to 3.0.1
- [Release notes](https://github.com/duo-labs/py_webauthn/releases)
- [Changelog](https://github.com/duo-labs/py_webauthn/blob/master/CHANGELOG.md)
- [Commits](duo-labs/py_webauthn@v3.0.0...v3.0.1)

Updates `oracledb` from 26.0.0 to 26.0.1
- [Release notes](https://github.com/oracle/python-oracledb/releases)
- [Commits](oracle/python-oracledb@v26.0.0...v26.0.1)

Updates `pymongo` from 4.18.1 to 4.18.2
- [Release notes](https://github.com/mongodb/mongo-python-driver/releases)
- [Changelog](https://github.com/mongodb/mongo-python-driver/blob/main/doc/changelog.rst)
- [Commits](mongodb/mongo-python-driver@4.18.1...4.18.2)

Updates `snowflake-connector-python` from 4.7.4 to 4.7.5
- [Release notes](https://github.com/snowflakedb/snowflake-connector-python/releases)
- [Commits](snowflakedb/snowflake-connector-python@v4.7.4...v4.7.5)

Updates `pillow-heif` from 1.7.0 to 1.8.0
- [Release notes](https://github.com/bigcat88/pillow_heif/releases)
- [Changelog](https://github.com/bigcat88/pillow_heif/blob/master/CHANGELOG.md)
- [Commits](bigcat88/pillow_heif@v1.7.0...v1.8.0)

Updates `opentelemetry-api` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-sdk` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-exporter-otlp` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-instrumentation-fastapi` from 0.65b0 to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-sqlalchemy` from 0.65b0 to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-logging` from 0.65b0 to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `hypothesis` from 6.168.0 to 6.168.1
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.168.0...v6.168.1)

Updates `httpx2` from 2.13.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.13.0...v2.13.1)

Updates `markdown` from 3.10.3 to 3.11
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.10.3...3.11.0)

Updates `ruff` from 0.16.8 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

Updates `httpcore2` from 2.13.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Commits](pydantic/httpx2@v2.13.0...v2.13.1)

Updates `platformdirs` from 4.11.11 to 4.11.14
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.11...4.11.14)

Updates `soupsieve` from 2.9.2 to 2.10
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](facelessuser/soupsieve@2.9.2...2.10)

Updates `virtualenv` from 21.9.0 to 21.12.1
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.9.0...21.12.1)

---
updated-dependencies:
- dependency-name: fonttools
  dependency-version: 4.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: pyparsing
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: sqlalchemy
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: webauthn
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: oracledb
  dependency-version: 26.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: pymongo
  dependency-version: 4.18.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: snowflake-connector-python
  dependency-version: 4.7.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: pillow-heif
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-api
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-sdk
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-exporter-otlp
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-instrumentation-fastapi
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-instrumentation-sqlalchemy
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-instrumentation-logging
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: uv-minor-patch
- dependency-name: hypothesis
  dependency-version: 6.168.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: httpx2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: markdown
  dependency-version: '3.11'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: httpcore2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: platformdirs
  dependency-version: 4.11.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: soupsieve
  dependency-version: '2.10'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: virtualenv
  dependency-version: 21.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

requirements.txt / pylock.toml drift (unsigned push blocked)

uv.lock / pyproject.toml changed but GitHub Actions cannot push an unsigned commit under the required_signatures ruleset (#1419).

Option A — signed commit on this Dependabot branch:

git fetch origin pull/2030/head:dependabot-review
git checkout dependabot-review
uv export --frozen --no-emit-project -o requirements.txt
uv export --format pylock.toml --frozen --all-extras --all-groups --output-file pylock.toml
git add requirements.txt pylock.toml
git commit -S -m "chore(deps): regenerate requirements.txt and pylock.toml after uv.lock update"
git push origin "HEAD:<dependabot-branch-name>"

Option B — supersede PR: apply the bump + export locally with signed commits (see CONTRIBUTING.md).

Download the CI-generated requirements.txt and pylock.toml from the workflow artifact on this run when present.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants